Junglewise Threat Intelligence

CVE-2026-21434: GO-2026-4485 - webtransport-go: Memory Exhaustion Attack due to Missing Length Check in WT_CLOSE_SESSION Capsule in github.com/quic-go/webtransport-go

CVE-2026-21434 · Severity: low · CVSS 3.1 · Published 2026-02-19

Technologies: github.com/quic-go/webtransport-go (Go). Vendors: Go.

Executive brief

webtransport-go: Memory Exhaustion Attack due to Missing Length Check in WT_CLOSE_SESSION Capsule in github.com/quic-go/webtransport-go

Affected products

  • Go github.com/marten-seemann/webtransport-go
  • Go github.com/quic-go/webtransport-go

Related threats